nerdexam
Microsoft

AZ-801 · Question #98

Hotspot Question You have an on-premises server named Server1 and a Microsoft Sentinel instance. You plan to collect Windows Defender Firewall events from Server1 and analyze the event data by using…

This question tests knowledge of how to onboard an on-premises Windows server to Microsoft Sentinel for log collection. It specifically asks what agent to deploy and what credentials are required during setup.

Secure Windows Server on-premises and hybrid infrastructures

Question

Hotspot Question You have an on-premises server named Server1 and a Microsoft Sentinel instance. You plan to collect Windows Defender Firewall events from Server1 and analyze the event data by using Microsoft Sentinel. What should you install on Server1, and which information should you provide during the installation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Explanation

This question tests knowledge of how to onboard an on-premises Windows server to Microsoft Sentinel for log collection. It specifically asks what agent to deploy and what credentials are required during setup.

Approach. You must install the Log Analytics Agent (also called the Microsoft Monitoring Agent / MMA) on Server1. This agent acts as the bridge between the on-premises server and the Log Analytics workspace that backs Microsoft Sentinel. During installation, you must provide the Workspace ID and the Primary Key (Workspace Key) - both found in the Log Analytics workspace under 'Agents management'. These two values authenticate and route Server1's telemetry to the correct Sentinel-connected workspace, enabling the Windows Defender Firewall events (collected via the Windows Firewall data connector) to appear in Sentinel for analysis.

Concept tested. Microsoft Sentinel on-premises agent deployment - specifically, that the Log Analytics Agent (MMA) is installed on non-Azure Windows servers, and that the Workspace ID + Primary Key are the required credentials to associate the agent with the correct Log Analytics workspace backing Sentinel.

Reference. Microsoft Learn - Connect Windows hosts to Microsoft Sentinel: https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/windows-firewall

Topics

#Microsoft Sentinel#Log Collection#Azure Monitor Agent#Windows Defender Firewall

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice